CVE-2023-34566: Critical severity Tenda Ac10 Firmware vulnerability
Published Jun 8, 2023
·Updated
Tenda AC10 v4 USAC10V4.0siV16.03.10.13cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.
Affected Software
4 affected components
All of the following
Tenda Ac10 Firmware=us_ac10v4.0si_v16.03.10.13_cn
Tenda AC10=4.0
Tenda Ac10 Firmware=us_ac10v4.0si_v16.03.10.13_cn
Tenda AC10=4.0
Event History
Jun 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34566?
CVE-2023-34566 is a vulnerability discovered in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn firmware that allows for a stack overflow via the 'time' parameter in the /goform/saveParentControlInfo endpoint.
2
How severe is CVE-2023-34566?
CVE-2023-34566 has a severity rating of 9.8, which is classified as critical.
3
What software versions are affected by CVE-2023-34566?
Tenda AC10 v4 firmware version US_AC10V4.0si_V16.03.10.13_cn is affected by CVE-2023-34566.
4
How can CVE-2023-34566 be exploited?
CVE-2023-34566 can be exploited by sending a specially crafted request to the /goform/saveParentControlInfo endpoint with a malicious 'time' parameter, causing a stack overflow.
5
Is Tenda AC10 version 4.0 affected by CVE-2023-34566?
No, Tenda AC10 version 4.0 is not affected by CVE-2023-34566.